From 89b67e0d97f663d0fec42e315fbd572bacd3947e Mon Sep 17 00:00:00 2001
From: Hyo
- Β© 2025{" "}
+ Β© {new Date().getFullYear()}{" "}
-
- The IAPKit repository is private, which normally prevents
- code-assistants from reasoning about it. Serving the reference as
- plain text at a stable URL means any LLM-powered editor (Claude Code,
- Cursor, Zed, Continue, etc.) that supports URL loaders can still pull
- in accurate context without repo access.
+ IAPKit is open source, but pointing an assistant at the monorepo costs
+ a lot of tokens to answer a one-line API question. Serving a condensed
+ reference as plain text at a stable URL lets any LLM-powered editor
+ (Claude Code, Cursor, Zed, Continue, etc.) that supports URL loaders
+ pull accurate context in one fetch.
+
diff --git a/libraries/expo-iap/example/scripts/vega-build-config.mjs b/libraries/expo-iap/example/scripts/vega-build-config.mjs
index 2399ee801..666dc2072 100644
--- a/libraries/expo-iap/example/scripts/vega-build-config.mjs
+++ b/libraries/expo-iap/example/scripts/vega-build-config.mjs
@@ -65,4 +65,11 @@ id = "/com.amazonappstore.iap.tester@IIAPTesterUI"
[needs]
[[needs.module]]
id = "/com.amazon.kepler.appstore.iap.purchase.core@IAppstoreIAPPurchaseCoreService"
+
+[[needs.module]]
+id = "/com.amazon.vega.os@IVega_1_2"
+
+[os.version]
+target = "1.2"
+min = "1.2"
`;
diff --git a/libraries/expo-iap/plugin/__tests__/withIAP.test.ts b/libraries/expo-iap/plugin/__tests__/withIAP.test.ts
index 137d261de..7c502ac65 100644
--- a/libraries/expo-iap/plugin/__tests__/withIAP.test.ts
+++ b/libraries/expo-iap/plugin/__tests__/withIAP.test.ts
@@ -896,6 +896,8 @@ describe('vega project generation', () => {
expect(manifest).toContain(
'id = "/com.amazon.kepler.appstore.iap.purchase.core@IAppstoreIAPPurchaseCoreService"',
);
+ expect(manifest).toContain('id = "/com.amazon.vega.os@IVega_1_2"');
+ expect(manifest).toContain('[os.version]\ntarget = "1.2"\nmin = "1.2"');
expect(createVegaEntryPoint()).toContain(
'AppRegistry.registerComponent(appName, () => App);',
);
diff --git a/libraries/expo-iap/plugin/src/withVega.ts b/libraries/expo-iap/plugin/src/withVega.ts
index 64dd240c9..ab5fe64be 100644
--- a/libraries/expo-iap/plugin/src/withVega.ts
+++ b/libraries/expo-iap/plugin/src/withVega.ts
@@ -13,6 +13,9 @@ const DEFAULT_ICON_FILE = 'icon.png';
const DEFAULT_BUILD_TYPE = 'Release';
const DEFAULT_RUNTIME_MODULE =
'/com.amazon.kepler.keplerscript.runtime.loader_2@IKeplerScript_2_0';
+// Vega SDK 0.24 requires both the OS module and an [os.version] block.
+const VEGA_OS_MODULE = '/com.amazon.vega.os@IVega_1_2';
+const VEGA_OS_VERSION = '1.2';
const logOnce = (() => {
const printed = new Set
+
diff --git a/libraries/godot-iap/README.md b/libraries/godot-iap/README.md
index 0f324f2da..2720f44d1 100644
--- a/libraries/godot-iap/README.md
+++ b/libraries/godot-iap/README.md
@@ -9,11 +9,11 @@
[](https://openiap.dev)
[](https://opensource.org/licenses/MIT)
-A comprehensive in-app purchase plugin for Godot 4.x that conforms to the Open IAP specification
+A comprehensive in-app purchase plugin for Godot 4.x that conforms to the OpenIAP specification
Requires Godot 4.3+, iOS 17+ for the Swift GDExtension, or Android API 24+.
-
+
diff --git a/libraries/kmp-iap/README.md b/libraries/kmp-iap/README.md
index b82e6beeb..93cbb615e 100644
--- a/libraries/kmp-iap/README.md
+++ b/libraries/kmp-iap/README.md
@@ -8,9 +8,9 @@
- A comprehensive Kotlin Multiplatform library for in-app purchases on Android and iOS platforms that conforms to the Open IAP specification
+ A comprehensive Kotlin Multiplatform library for in-app purchases on Android and iOS platforms that conforms to the OpenIAP specification
-
+
## π Documentation
diff --git a/libraries/react-native-iap/README.md b/libraries/react-native-iap/README.md
index 607b9b609..11630c533 100644
--- a/libraries/react-native-iap/README.md
+++ b/libraries/react-native-iap/README.md
@@ -5,9 +5,9 @@
[](https://npmjs.org/package/react-native-iap) [](https://npmjs.org/package/react-native-iap) [](https://openiap.dev) [](https://opencollective.com/openiap) [](https://github.com/hyodotdev/openiap/actions/workflows/ci-react-native-iap.yml?query=branch%3Amain) [](https://app.codecov.io/gh/hyodotdev/openiap/tree/main/libraries/react-native-iap) [](https://app.fossa.com/projects/git%2Bgithub.com%2Fhyochan%2Freact-native-iap?ref=badge_shield&issueType=license)
-**React Native IAP** is a high-performance in-app purchase library using Nitro Modules that **conforms to the [Open IAP specification](https://openiap.dev)**. It provides a unified API for handling in-app purchases across iOS and Android platforms with comprehensive error handling and modern TypeScript support.
+**React Native IAP** is a high-performance in-app purchase library using Nitro Modules that **conforms to the [OpenIAP specification](https://openiap.dev)**. It provides a unified API for handling in-app purchases across iOS and Android platforms with comprehensive error handling and modern TypeScript support.
-
+
## π Documentation
diff --git a/libraries/react-native-iap/example/manifest.toml b/libraries/react-native-iap/example/manifest.toml
index 3c911981b..2a1f4d328 100644
--- a/libraries/react-native-iap/example/manifest.toml
+++ b/libraries/react-native-iap/example/manifest.toml
@@ -34,3 +34,10 @@ id = "/com.amazonappstore.iap.tester@IIAPTesterUI"
[needs]
[[needs.module]]
id = "/com.amazon.kepler.appstore.iap.purchase.core@IAppstoreIAPPurchaseCoreService"
+
+[[needs.module]]
+id = "/com.amazon.vega.os@IVega_1_2"
+
+[os.version]
+target = "1.2"
+min = "1.2"
diff --git a/package.json b/package.json
index 9659db3a6..c48048c2e 100644
--- a/package.json
+++ b/package.json
@@ -14,6 +14,7 @@
"e2e:web": "node scripts/e2e-web-sites.mjs",
"audit:deprecations": "node --test scripts/audit-deprecation-schedule.test.mjs && node scripts/audit-deprecation-schedule.mjs",
"audit:layout": "node --test scripts/audit-repo-layout.test.mjs && node scripts/audit-repo-layout.mjs",
+ "audit:ci-paths": "node --test scripts/audit-ci-path-filters.test.mjs && node scripts/audit-ci-path-filters.mjs",
"audit:parity": "node scripts/audit-non-godot-parity.mjs",
"audit:kit-contract": "node --test scripts/audit-kit-spec-contract.test.mjs && node scripts/audit-kit-spec-contract.mjs",
"audit:docs": "bun run scripts/audit-docs.ts",
diff --git a/packages/docs/README.md b/packages/docs/README.md
index 25918f118..0da7bb6f3 100644
--- a/packages/docs/README.md
+++ b/packages/docs/README.md
@@ -16,15 +16,16 @@ Visit [openiap.dev](https://openiap.dev) for full documentation.
## Sponsors
+
diff --git a/packages/docs/src/components/EcosystemDiagram.tsx b/packages/docs/src/components/EcosystemDiagram.tsx
index f80efd36c..6bca0d829 100644
--- a/packages/docs/src/components/EcosystemDiagram.tsx
+++ b/packages/docs/src/components/EcosystemDiagram.tsx
@@ -199,12 +199,12 @@ function Rail({
variant,
label,
}: {
- variant: 'a' | 'b' | 'bypass' | 'iapkit';
- label: string;
+ variant: 'a' | 'b' | 'bypass' | 'iapkit' | 'iapkit-core';
+ label?: string;
}) {
return (
);
}
@@ -336,6 +336,7 @@ function EcosystemDiagram() {
+ ~3 KB
+ ~14 KB
@@ -68,19 +68,19 @@ export default function AiAssistantsPage() {
table, error body shape, structured log line, retry policy,
Sentry config, Convex data model, deployment.
- ~9 KB
+ ~25 KB
- Grant or fulfill only when isValid === true, the harmonized
- state permits that operation, and the store-verified
+ Grant or fulfill only when isValid === true, the harmonized{" "}
+ state permits that operation, and the store-verified{" "}
productId is present and matches the product your app
expected. For Meta Horizon, productId is the SKU IAPKit
checked. Amazon responses also identify the server-selected{" "}
@@ -433,10 +433,12 @@ async function refreshEntitlements(
originalTransactionId explicitly.
- Administrative subscription endpoints use{" "}
- Authorization: Bearer openiap-kit_sk_.... Compatibility
- routes with a key in the path remain available, but new server-side and
- MCP integrations should keep secret keys out of URLs.
+ Administrative subscription endpoints require{" "}
+ Authorization: Bearer openiap-kit_sk_.... IAPKit never
+ accepts a secret key in a URL β a secret key in a path returns{" "}
+ 410 SECRET_API_KEY_IN_URL. The compatibility routes that
+ keep a key in the path accept publishable keys only, for SDK runtimes
+ that strip request headers.